Legal
Privacy policy
How WarmDispatch handles the information that flows through text campaigns, SMS conversations and booking.
Last updated: September 27, 2026
1. Who we are
WarmDispatch LLC, a California limited liability company (“WarmDispatch,” “we,” “us”), provides automated text campaigns, missed-call text-back and appointment-booking services to salons, med spas, specialty spas and similar appointment-based businesses (“Customers”). WarmDispatch LLC is the business responsible for this website and for the personal information described in this policy, and is the data controller for Customer information. This policy describes how we handle personal information for two groups of people: our Customers (the businesses who subscribe), and the clients and prospective clients who are messaged by or contact those Customers (“End Users”).
For End User data, the Customer is the controller of the information and we act as a processor on their instructions. If you are a client who received a text message, the business whose name appears in the message is responsible for that communication.
2. SMS consent and opt-out
Text messaging is the core of this service, so it gets its own section.
- Consent. Our Customers are responsible for obtaining and documenting consent for recurring SMS from every person they message, and for complying with the Telephone Consumer Protection Act (TCPA), applicable state law, and their carrier’s messaging requirements. We provide consent-status tracking, but we do not obtain consent on a Customer’s behalf.
- Disclosure in messages. Every automated message template we ship includes the sending business name and opt-out language: “Reply STOP to opt out.” Message and data rates may apply. Message frequency varies with the conversation.
- Opt-out. Replying STOP, STOPALL, UNSUBSCRIBE, CANCEL, END or QUIT to any message ends automated messaging from that number. The opt-out is honored immediately and applied across every automation on the account. Replying START re-subscribes. Replying HELP returns the business’s contact information.
- Marketing messages require express written consent. Promotional campaigns (such as offers, win-back and birthday messages) are sent only to End Users for whom the Customer has obtained and documented prior express written consent to receive marketing texts. Appointment-related messages are sent only in connection with a client relationship or inbound inquiry.
- Quiet hours. Automated sends are suppressed between 9:00 PM and 8:00 AM in the Customer’s configured time zone by default.
- Carrier sharing. Mobile information is not sold, and consent for SMS is not shared with third parties or affiliates for their own marketing purposes. It is shared only with the messaging providers required to deliver the message.
3. Information we process
From Customers: business name, contact name, email address, phone numbers, billing details processed by our payment provider, team member names and roles, service-area ZIP codes, office hours, escalation contacts, and message templates.
From End Users, on behalf of Customers: phone number, name, visit history (such as last visit date and service category), birthday month if the Customer provides it, messages in their own words, whether they are a new or existing client, appointment details, SMS message content and timestamps, call metadata (time, duration, answered or missed), consent and opt-out status, and lead source.
Automatically: log data, device and browser information, IP address, and product usage events needed to operate and secure the service.
From new Customers who complete our onboarding form: business legal name, EIN, business structure, address, website, contact names, emails and phone numbers, booking software and link, hours, services and prices, campaign preferences, approximate client-list size, how the business collects texting consent, and a typed signature. We use this to set up the service and to complete carrier (A2P 10DLC) registration for the Customer’s texting number. The submission is delivered by email through Resend, with Formspree as a backup.
From website visitors who request a pilot: the business name, contact name, email, phone number, business type, number of providers, booking software and free-text description you enter in the pilot request form, plus your consent to be contacted. That submission is delivered to our inbox as an email sent through Resend, our email delivery provider. If that delivery fails, the submission falls back to Formspree, a third-party form processor, which stores the submission and forwards it to us. We use it only to contact you about the pilot you requested. Ask us at support@warmdispatch.com and we will delete it.
We do not intentionally collect government identification numbers, financial account numbers, precise geolocation or biometric data. By default, messages refer to “your appointment” rather than naming a treatment, and we ask Customers not to send detailed health or treatment information through the service. Customers that are HIPAA covered entities (for example, some medical spas) must not send protected health information through the service unless a business associate agreement is in place. If an End User volunteers health-related information in a reply, it is stored as free text in the conversation record, treated as sensitive, and used only to respond to that person.
4. How we use information
- To send automated text-back and follow-up messages on the Customer’s behalf.
- To generate suggested message drafts, classify replies, and detect keywords that may indicate a medical concern requiring prompt human attention.
- To create lead records, book appointments, and send reminders and follow-ups.
- To provide account reporting to the Customer.
- To bill Customers, provide support, prevent abuse, and meet legal obligations.
We do not sell personal information, and we do not use End User message content to train third-party foundation models. Message content sent to an AI provider for reply drafting or classification is transmitted under agreements that prohibit its use for model training.
5. Automated processing and its limits
The service uses automated decision-making in a limited way: it classifies inbound messages, drafts replies, offers appointment windows within rules the Customer configures, and flags potential safety emergencies for human handling. These automated outputs are constrained so that the system does not diagnose equipment faults, does not diagnose or advise on hazards beyond directing a person to leave and contact emergency services, does not quote prices, and does not promise arrival times outside published availability. Customers can require human approval before any message is sent.
The service is not a medical, monitoring, or emergency-response system. It only reacts to what a person types, and it does not provide medical advice.
6. Sharing
We share information with service providers that make the product work, each under contract and only for the purpose described:
- Messaging and telephony — to deliver and receive SMS and to detect missed calls.
- AI providers — to draft replies and classify message content.
- Booking and calendar tools — where the Customer connects or exports from them, to identify open slots and rebooking timing.
- Payment processing — to bill Customer subscriptions. We do not store full card numbers.
- Cloud hosting, logging and error monitoring.
- Email delivery — Resend transmits pilot requests submitted on this website to our inbox.
- Form processing — Formspree receives and forwards pilot requests as a backup if email delivery fails.
We may also disclose information when required by law, to enforce our terms, or in connection with a merger or acquisition, in which case we will provide notice.
7. Retention
Lead records, message transcripts and call metadata are retained for the life of the Customer’s account and for 90 days after termination, after which they are deleted or de-identified. Opt-out records are retained longer, because we are required to keep them to continue honoring the opt-out. Billing records are retained as required by tax and accounting rules. Customers can export their data as CSV at any time and can request earlier deletion of specific records.
8. Security
We use encryption in transit and at rest, role-based access control, least-privilege internal access, audit logging, and periodic review of third-party providers. No system is perfectly secure; we will notify affected Customers without undue delay if a breach affecting their data occurs.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to opt out of sale or sharing (we do not sell), and to be free from discrimination for exercising those rights. End Users should contact the business that messaged them, since that business controls the record; we will assist that business in responding. Customers can contact us directly at the address below.
10. Children
The service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
11. International
The service is operated from California in the United States by WarmDispatch LLC and is intended for use by U.S. businesses. If you access it from elsewhere, you consent to processing in the United States.
12. Changes and contact
We will post material changes to this policy on this page and update the “last updated” date. Questions about privacy, consent records, or a data request, including requests under the California Consumer Privacy Act, can be sent to WarmDispatch LLC at support@warmdispatch.com. Our mailing address is available on request at that address.